The hook_process() function does not properly handle shell expansions
(CVE-2012-5534).

WeeChat does not properly decode colors which could cause a
heap-based buffer overflow (CVE-2012-5854).

Impact

A remote attacker could entice a user to open a specially crafted script
or send messages with specially crafted colors, possibly resulting in
execution of arbitrary code with the privileges of the process, or a
Denial of Service condition.